Berkeley MPEG Tools Insecure Temporary File Creation Vulnerabilities
BID:15002
Info
Berkeley MPEG Tools Insecure Temporary File Creation Vulnerabilities
| Bugtraq ID: | 15002 |
| Class: | Design Error |
| CVE: |
CVE-2005-3115 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 03 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovery is credited to Mike Frysinger of the Gentoo Security Team. |
| Vulnerable: |
Gentoo Linux Berkeley MPEG Tools Berkeley MPEG Tools 1.5 b |
| Not Vulnerable: | |
Discussion
Berkeley MPEG Tools Insecure Temporary File Creation Vulnerabilities
Berkeley MPEG Tools creates temporary files in an insecure manner.
Successful exploitation may result in sensitive data or configuration files being overwritten. This may result in a denial of service due to data corruption; other attacks may also be possible.
Berkeley MPEG Tools 1.5b is known to be vulnerable at the moment. Other versions may be affected as well.
Berkeley MPEG Tools creates temporary files in an insecure manner.
Successful exploitation may result in sensitive data or configuration files being overwritten. This may result in a denial of service due to data corruption; other attacks may also be possible.
Berkeley MPEG Tools 1.5b is known to be vulnerable at the moment. Other versions may be affected as well.
Exploit / POC
Berkeley MPEG Tools Insecure Temporary File Creation Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
Berkeley MPEG Tools Insecure Temporary File Creation Vulnerabilities
Solution:
Gentoo has released advisory GLSA 200510-02 to address these issues. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=media-video/mpeg-tools-1.5b-r2"
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Gentoo has released advisory GLSA 200510-02 to address these issues. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=media-video/mpeg-tools-1.5b-r2"
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Berkeley MPEG Tools Insecure Temporary File Creation Vulnerabilities
References:
References:
- Home Page (Berkeley MPEG Tools)